news.volyx.in

Unpacking Google’s Web Environment Integrity specification (vivaldi.com)

756 points by dagurp · 1127 days ago · 433 comments on HN

Article summary

Google's proposed Web Environment Integrity (WEI) specification has raised concerns among browser developers and users, as it could potentially allow websites to restrict access based on the user's browser and platform. The specification would provide an API for websites to verify the authenticity of user interactions, but critics argue that it could be used to exclude certain browsers or platforms. The proposal has been likened to DRM for the web, and some argue that it could lead to a loss of user freedom and choice. Google has since announced that it will not proceed with the WEI specification, but some commentators remain skeptical about the company's intentions.

Main themes

  • Web Environment Integrity
  • browser freedom
  • DRM for the web
  • user choice and control
  • security and authentication
  • monopolistic control
  • open web and standards
  • TPMs and attestation

What commenters say

  • The WEI specification is a threat to the open web and could lead to a loss of user freedom and choice.
  • The proposal is necessary to prevent fake interactions with websites and ensure the integrity of online services.
  • The use of TPMs and attestation is a legitimate security measure, but it should not be used to restrict user choice or control.
  • The WEI specification is a form of DRM for the web and could be used to exclude certain browsers or platforms.
  • Google's decision not to proceed with the WEI specification is a positive development, but the company's intentions and future plans remain unclear.
  • The use of WEI could lead to a two-tiered web, where users without approved browsers or platforms are relegated to second-class citizenship.
  • The proposal raises concerns about monopolistic control over the web and the potential for abuse of power by large corporations.
  • Alternative solutions to the problem of fake interactions, such as improved security measures and better user authentication, should be explored instead of relying on restrictive technologies like WEI.